Information-sharing and data-protection protocol

The terms under which competing banks, insurers and critical-infrastructure operators exchange information during a joint executive crisis exercise. Published so that legal, compliance and data-protection functions can review it before their executives take part.

  1. 1. Purpose and scope

    This protocol governs the exchange of information between organisations taking part in a joint executive crisis exercise on this platform. It covers the exercise itself, the facilitator console, the debrief, and any cross-organisation analysis derived from a session.

    It does not govern real-incident information sharing. Exercise participation creates no obligation, and no channel, for sharing live incident intelligence between participants.

  2. 2. What is shared between organisations

    Decisions taken in a shared session room, attributed to a seat and an organisation, are visible to every participant in that room in real time. That visibility is the point of the exercise.

    Cross-organisation analysis — the Divergence Index, per-axis averages, and the Return on Mitigation aggregate — is shared with all participating organisations after the session.

    Aggregate figures are computed only across runs scored on the locked flagship benchmark table. Runs using an organisation's own local assumptions are counted, footnoted and excluded from the shared aggregate.

  3. 3. What is never shared

    No real production data, real incident data, real customer data, real system inventories, real vulnerability findings or real supplier contracts are ever entered into or held by the platform. Scenarios are synthetic.

    An organisation's local benchmark assumptions, its internal notes, and its own private runs outside a cohort session are not visible to other participants.

    Individual participant scores are not disclosed to other organisations. Cross-organisation reporting is at organisation level only.

  4. 4. Attribution rule

    Sessions run under a modified Chatham House Rule. Inside the session room, decisions are attributed so that participants can see who diverged and discuss it.

    Outside the session, participants may use the substance of what was discussed but may not attribute a decision, statement or weakness to another named organisation or individual without that organisation's written consent.

    Exported artefacts — PDF debriefs, scorecards and shareable links — carry this restriction on their face.

  5. 6. Competition-law guardrails

    Joint exercises between competing institutions are limited to operational resilience and crisis response. Pricing, commercial terms, customer allocation, market strategy and any other commercially sensitive parameter are out of scope, and facilitators are instructed to stop discussion that moves toward them.

    Scenario options are written so that no realistic path requires disclosure of commercially sensitive information.

  6. 7. Retention and deletion

    Live session rooms and their real-time state expire automatically 24 hours after creation.

    Cohort submissions, debrief results and corrective actions are retained for the duration of the programme and for 24 months afterwards, so that a retest can be compared with the original run.

    A participating organisation may request deletion of its own submissions at any time; the shared aggregate is then recomputed without them.

  7. 8. Access control

    Participant access is by individual invitation token or by an approved access request. Facilitator and administrative functions require a separate facilitator credential or an administrator account.

    Row-level access rules restrict every organisation to its own records; cross-organisation analysis is produced server-side and released only in the agreed aggregate form.

    External stakeholder seats — supervisor, regulator, law enforcement, provider, auditor — are invited explicitly by the facilitator for a named session and see only that session.

  8. 9. Participation undertaking

    Before a cohort session, each participating organisation confirms: it accepts this protocol; it will not attribute another participant's decisions externally without consent; it will not introduce real incident, customer or production data into the exercise; and it accepts that exercise results are indicative planning material, not assurance, certification or a prediction of real-incident performance.

    The confidentiality and ethics gate inside the platform records that confirmation before a participant can enter a shared room.